Skip to content
← archivevulnerability · 18 Sep 2026 · 17:58 UTC

GHSA-9jjc-fw8x-fmwx: io.moquette:moquette-broker has a Missing Authorization issue

VULNCVE-2026-85058source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

## Summary Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of disconnected clients. All normal PUBLISH paths (`receivedPublishQos0`, `receivedPublishQos1`, `receivedPublishQos2`) correctly invoke `authorizator.canWrite()` before publishing, but the Will message publishing path (`fireWill()` → `publishWill()` → `publish2Subscribers()`) completely bypasses this authorization check. …

CVE · detail
grounded ✓primary source ↗

● loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected